All Apps and Add-ons

Splunk Forwarder Service/ Windows Infrastructure App Causing PowerShell.exe to use 50% CPU + continuously growing Memory

mgrasber
Engager

Hi Guys - apologies ahead of time for my ignorance as I'm a rookie.

I have the splunk forwarder installed on a DC running 2012 R2. Service runs fine with no apps installed. When I stop the service, install TA-DNSServer-NT6 and TA-DomainController-NT6 for the windows infrastructure splunk app, and restart the service, Windows Powershell hovers consistently at 50+% CPU in task manager. Memory usage starts around a few hundred MB and grows by about 3mb/s without stopping. Right now it's at about 2050mb of memory.

All the correct information looks like it's being collected in splunk. I can see LDAP information, DS client binds, etc...

We have 2 other DCs on 2008 R2 that are forwarding information using the Splunk App For AD and the task manager shows no similarities.

Any help would be appreciated. Thanks!

0 Karma
1 Solution

mgrasber
Engager

I'm an idiot - Didn't even notice that there is an addon specifically for 2012 R2 that comes with this app (TA-DomainController-2012R2). Will leave this here just in case anyone else has the same brain fart. Thanks everyone.

View solution in original post

mgrasber
Engager

I'm an idiot - Didn't even notice that there is an addon specifically for 2012 R2 that comes with this app (TA-DomainController-2012R2). Will leave this here just in case anyone else has the same brain fart. Thanks everyone.

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...